Vulnerability record · CVE-2022-24637 · published 18 March 2022
CVE-2022-24637: Open Web Analytics unauthenticated info leak leading to admin takeover
Openwebanalytics · Open Web Analytics
Open Web Analytics before 1.7.4 mishandles generated files that begin with '<?php' instead of the intended '<?php' sequence, so the PHP interpreter does not execute them. An unauthenticated remote attacker can read sensitive user information from these files and use cache hashes to escalate to administrator privileges. The flaw is critical because it is network-reachable with no authentication or user interaction and leads to full compromise of confidentiality, integrity and availability.
Description
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network exploitation with a 9.8 CVSS score, near-maximum EPSS and public exploit references makes this an urgent patch.
What it is
Open Web Analytics before 1.7.4 mishandles generated files that begin with '<?php' instead of the intended '<?php' sequence, so the PHP interpreter does not execute them. An unauthenticated remote attacker can read sensitive user information from these files and use cache hashes to escalate to administrator privileges. The flaw is critical because it is network-reachable with no authentication or user interaction and leads to full compromise of confidentiality, integrity and availability.
Impact
An attacker gains sensitive user data and, by leveraging cache hashes, can obtain administrative privileges over the OWA installation. That yields control of the analytics application and any data or integrations it manages.
Attack surface
Reachable over the network via HTTP against the OWA web application; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to trigger the information disclosure.
Exploitation
Not listed in CISA KEV, but EPSS is 0.99055 (99.9th percentile) and multiple references are tagged Exploit, including public remote code execution write-ups for 1.7.3. Treat exploitation as likely and publicly demonstrated.
What to do
- Upgrade Open Web Analytics to 1.7.4 or later, which is the vendor release that addresses this issue.
- If immediate upgrade is not possible, restrict network access to the OWA instance to trusted management networks only.
- Review and rotate OWA administrator credentials and any secrets exposed through cached or generated files.
- Monitor the vendor advisory and release notes for any further guidance tied to 1.7.4.
Detection
- Inspect web server and OWA logs for unauthenticated requests to generated or cache file paths that return PHP source rather than executing.
- Search the OWA installation for files beginning with the malformed '<?php' sequence that are served as static content.
- Alert on anomalous administrative logins or privilege changes in OWA following suspicious unauthenticated requests.
- Hunt for outbound or follow-on activity consistent with the public 1.7.3 remote code execution exploit chains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/171389/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html | |
| https://devel0pment.de/?p=2494 | ExploitMitigationPatchThird Party Advisory |
| https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.7.4 | Release NotesThird Party Advisory |
| http://packetstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/171389/Open-Web-Analytics-1.7.3-Remote-Code-Execution.html | |
| https://devel0pment.de/?p=2494 | ExploitMitigationPatchThird Party Advisory |
| https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.7.4 | Release NotesThird Party Advisory |
Track CVE-2022-24637 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24637), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.